UI Patterns (SDC in Drupal UI)
The module does not properly clean the code passed to design components. An ordinary account on the site could use this to read some restricted data and change or add some data.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies if an attacker can create or update content displayed by the module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate UI Patterns (SDC in Drupal UI) to 2.0.17.
For developers: what the fix changed
The fix improves markup sanitisation by escaping untrusted strings in `LinksPropType`, `StringPropType`, `FieldPropertySource`, and `TokenSource`, and by using `#plain_text` instead of `#children` with `Markup::create()` for plain strings in `SlotPropType`. It also overrides Twig's `include()` function in `TwigExtension` to return a `Markup` object for consistent trust boundaries.
Also in this release The release also refactored plugin managers, added a `no_ui` property to sources, introduced a `SourceTags` enum, and improved test performance.
.cspell-project-words.txt+1 −0.gitlab-ci.yml+4 −1composer.json+3 −0config/schema/ui_patterns.schema.yml+12 −1config/schema/ui_patterns.sources.schema.yml+19 −0modules/ui_patterns_field/src/Plugin/Derivative/UIPatternsSourceFieldPropertySourceDeriver.php+1 −1modules/ui_patterns_field/src/Plugin/Field/FieldType/SourceValueItem.php+14 −1modules/ui_patterns_field/src/Plugin/Field/FieldWidget/SourceComponentWidget.php+2 −1modules/ui_patterns_field_formatters/config/schema/ui_patterns_field_formatters.sources.schema.yml+0 −18modules/ui_patterns_views/src/Plugin/UiPatterns/Source/ViewFieldSource.php+0 −1modules/ui_patterns_views/src/Plugin/UiPatterns/Source/ViewRowsSource.php+1 −1src/Attribute/Source.php+4 −0